Impact
A cryptographic flaw was identified in the integrity checks of Apple’s operating systems. The vulnerability allows an attacker with a privileged network position to modify intercepted traffic, potentially inserting or altering data before it reaches the target device. This weakness undermines the confidentiality and integrity of communications on the affected systems.
Affected Systems
Apple’s iOS, iPadOS, macOS, tvOS, and watchOS are impacted. The bug is resolved in the 27th revision of each platform: iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, and watchOS 27.
Risk and Exploitability
The CVSS score is 5.3. The EPSS score indicates a very low but non-zero exploitation probability (<1%). The vulnerability is not listed in CISA’s KEV catalog. An attacker must have a foothold in a privileged network segment to exploit the flaw, suggesting a limited but present attack surface. The potential impact remains the ability to tamper with network traffic destined for or originating from Apple devices, leading to data injection or compromise of secure communications.
OpenCVE Enrichment